Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Dotdeb PHP PHP_Self Path_Info Email Header Injection Vulnerability

Dotdeb PHP is prone to an email-header-injection vulnerability because it fails to properly sanitize user-supplied input when constructing email messages.

Exploiting this issue allows a malicious user to create an arbitrary email header, and then create and transmit spam messages from the affected computer.

PHP4 versions prior to 4.4.4 are vulnerable.
PHP5 versions prior to 5.2.0 rev 3 are vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus